Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.6 CVE-2025-71371

picklescan – Remote Code Execution via code.InteractiveInterpreter Detection Bypass_CVE-2025-71371

picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pi...

picklescan picklescan CVE
HIGH 7.6 CVE-2025-71368

picklescan – Arbitrary Code Execution via Undetected doctest.debug_script_CVE-2025-71368

picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary cod...

picklescan picklescan CVE
HIGH 7.6 CVE-2025-71363

picklescan – Arbitrary Code Execution via Undetected cProfile.run in Pickle Deserialization_CVE-2025-71363

picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote...

picklescan picklescan CVE
HIGH 7.6 CVE-2025-71355

Picklescan – Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass_CVE-2025-71355

Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and execute arb...

Picklescan Picklescan CVE
HIGH 7.6 CVE-2025-71352

picklescan – Remote Code Execution via Undetected trace.Trace.runctx in Pickle Files_CVE-2025-71352

picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods, allowing attacker...

picklescan picklescan CVE
HIGH 7.6 CVE-2025-71350

picklescan – Undetected Remote Code Execution via torch.utils.collect_env.run_CVE-2025-71350

picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed u...

picklescan picklescan CVE
HIGH 7.6 CVE-2025-71349

picklescan – Arbitrary Code Execution via Undetected trace.Trace.run in Pickle Files_CVE-2025-71349

picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected ...

picklescan picklescan CVE
CRITICAL 10 CVE-2026-56415

OS Command Injection in StoneFly Storage Concentrator_CVE-2026-56415

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A ...

Stonefly Storage Concentrator CVE
CRITICAL 10 CVE-2026-56413

OS Command Injection in StoneFly Storage Concentrator_CVE-2026-56413

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default...

StoneFly Storage Concentrator CVE
CRITICAL 9.2 CVE-2026-55721

SQL Injection in StoneFly Storage Concentrator_CVE-2026-55721

Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie va...

StoneFly Storage Concentrator CVE